preludedb-admin delete alert
"Schubert, Aaron" <[email protected]> Wed, 19 Jan 2011 09:28:51 -0600
| Newsgroups | gmane.comp.security.ids.prelude.user |
|---|---|
| Message-ID | <950F909D7BFFA041A0714E004BE2E96528C1653218@EXCHVS5A.mx.state.mo.us> |
I issue the command, preludedb-admin delete alert "type=mysql name=xxxxx user=xxxxx pass=xxxxx" --criteria "alert.create_time < 2011-01-19", and it just sits there for days deleting events. In the meantime the database is still growing. By completion of the prelude implementation I will be taking in over 100 million events per day between snort and reading firewall logs. Is there a way to just truncate the tables? If so, what tables do I truncate and which do I leave alone without messing up the system. Can I truncate events up to a certain time? Basically is there a quicker way to trim the DB? _______________________________________________ Prelude-user site list [email protected] http://lists.prelude-technologies.com/mailman/listinfo/prelude-user